[Bug 1231186] New: VUL-0: CVE-2024-47515: pagure: generate_archive() follows symbolic links in temporary clones
https://bugzilla.suse.com/show_bug.cgi?id=1231186 Bug ID: 1231186 Summary: VUL-0: CVE-2024-47515: pagure: generate_archive() follows symbolic links in temporary clones Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/422443/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: dominik@wombacher.cc Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: camila.matos@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This results in the ability to craft valid administrator sessions and take over the Pagure instance. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-47515 https://bugzilla.redhat.com/show_bug.cgi?id=2315806 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231186 https://bugzilla.suse.com/show_bug.cgi?id=1231186#c1 --- Comment #1 from Camila Camargo de Matos <camila.matos@suse.com> --- The following packages are affected by this issue: - openSUSE:Backports:SLE-15-SP5/pagure - openSUSE:Backports:SLE-15-SP6/pagure Package openSUSE:Factory/pagure already contains the fix. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231186 https://bugzilla.suse.com/show_bug.cgi?id=1231186#c2 --- Comment #2 from Camila Camargo de Matos <camila.matos@suse.com> --- Fix available at: https://pagure.io/pagure/c/9b715170008bdc1dd273f7c28debe782a8f7969e?branch=5... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231186 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com